SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#259785

AWStats fails to validate input supplied to pluginmode parameter

Overview

AWStats performs inadequate validation on user-controlled data that is supplied to the pluginmode parameter. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary commands.

I. Description

AWStats is a Perl CGI script that collects and graphically displays statistics from web, FTP, and mail servers. AWStats provides the ability to extend its functionality via plug-ins. Inadequate validation on input supplied to the pluginmode parameter may allow an attacker to execute PERL commands (i.e. the system() function), which can be used to execute arbitrary operating system or shell commands with the privileges of the web server process.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary commands or cause a denial-of-service condition.

III. Solution

Upgrade

According to public reports, this vulnerability was corrected in AWStats version 6.4. While this version is available to the public, it is still considered under development (beta). Users are encouraged to consult the AWStats Download page for more information.

Systems Affected

VendorStatusDate Updated
AWStatsVulnerable25-Feb-2005

References


http://packetstorm.linuxsecurity.com/0501-exploits/AWStatsVulnAnalysis.pdf
http://secunia.com/advisories/14299/
http://marc.theaimsgroup.com/?l=bugtraq&m=110840530924124&w=2
http://awstats.sourceforge.net/docs/awstats_changelog.txt
http://awstats.sourceforge.net/

Credit

This vulnerability was reported by GHC.

This document was written by Jeff Gennari.

Other Information

Date Public02/15/2005
Date First Published02/25/2005 04:14:53 PM
Date Last Updated02/25/2005
CERT Advisory 
CVE NameCAN-2005-0363
US-CERT Technical Alerts 
Metric8.00
Document Revision79

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader